CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,712 vulnerabilities with CWE-94
CVE-2026-46442
CRITICAL
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVSS 9.9
CVE-2026-11520
LOW
SourceCodester Inventory System header.php cross site scripting
CVSS 3.5
CVE-2026-11518
MEDIUM
SourceCodester Inventory System User Management users.php cross site scripting
CVSS 4.3
CVE-2026-11512
MEDIUM
itsourcecode Hospital Management System billing.php cross site scripting
CVSS 4.3
CVE-2026-11491
LOW
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
CVSS 2.4
CVE-2026-11468
LOW
SourceCodester Hospitals Patient Records Management System page room_types cross site scripting
CVSS 2.4
CVE-2026-11436
MEDIUM
Mage AI Sign-in Flow index.tsx useMutation cross site scripting
CVSS 4.3
CVE-2026-11434
LOW
FluentCMS Blocks Plugin blocks cross site scripting
CVSS 2.4
CVE-2026-49493
HIGH
Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()
CVSS 8.8
CVE-2026-11338
LOW
SourceCodester Ship Ferry Ticket Reservation System manage_user cross site scripting
CVSS 2.4
CVE-2026-11337
MEDIUM
tittuvarghese CollegeManagementSystem fetch.php cross site scripting
CVSS 4.3
CVE-2026-11231
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.1
CVE-2026-11218
MEDIUM
Google Chrome - Arbitrary Code Execution
CVSS 6.8
CVE-2026-11157
MEDIUM
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 5.4
CVE-2026-10928
HIGH
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-10904
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-41249
HIGH
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
CVSS 8.2
CVE-2026-10810
MEDIUM
itsourcecode Fees Management System navbar.php cross site scripting
CVSS 4.3
CVE-2026-10688
MEDIUM
ahujasid blender-mcp server.py execute_blender_code code injection
CVSS 5.5
CVE-2026-49143
HIGH
BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler
CVSS 8.8
CVE-2026-1829
HIGH
Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
CVSS 8.8
CVE-2026-47117
CRITICAL
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
CVSS 9.8
CVE-2026-10567
LOW
1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting
CVSS 3.5
CVE-2026-10529
LOW
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
CVSS 2.4
CVE-2026-10514
LOW
1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting
CVSS 2.4
Details
Vulnerabilities
6,712
Exploit Likelihood
Medium